Repository navigation
docs(briefs): B4 — DeclarationRef consumer-migration reframe + umbrella tighten (post-#814 carry-forward) - #815
Conversation
…edger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…-1 status edits + char_in_class interpreter-parity sibling row from main
…audit note (PM review)
…-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2.
…lass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
… the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
… on signature-shape coverage Resolves codex BLOCKING at sha d49ce79 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656b partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…losed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be31) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
… (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be31 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa9 Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…d landed via #792 Resolves codex inline BLOCKING at sha 191be31 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…e P2 framing stale Resolves codex non-blocking finding at sha bcac41b on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b13 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Codex follow-up on sha 2552ca3: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…iguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…onnectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…trate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2ce's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
# Conflicts: # docs/briefs/b4-identity-carrier-substrate-pass.md
PM review — APPROVEThis is exemplary
NET delta vs main is exclusively B4 (B1/B2/B3 unchanged from squash-merged #814). Clean, focused follow-up. One housekeeping note: PR is currently in draft state. Once you're ready, flip with After this lands: B1, B2, B3 ready to dispatch in parallel; B4.1 ready to author against the consumer-migration framing; B4.2-B4.4 each begin with the authority-grep audit. |
|
Thanks. PR was flipped ready in |
|
Review metadata
Findings
Verdict |
…ost-#815 follow-up) (#816) * docs(roadmap): record CharClass phase-1 closure + add Class 5 Gap 3 ledger row (post-#693 escalation) Director-authored amendment following the 2026-04-24 escalation from PR #693 (sub-child sharp-bear-829 under Surface Manager). Two edits: 1. New "Class 5 Gap 3 — port-carried field values in data bodies" row in the 2026-04-21 post-merge-debt section. The substrate gap was documented in src/v3/DOWNSTREAM_REQUIREMENTS.md:239 but had no ROADMAP ledger row for cross-lane visibility. PR #693's execution surfaced it as the blocker on sub_charclass_in_std_unicode phase-2. 2. Retract the "ready-to-dispatch (no substrate capability gap)" claim on the Character-level row, annotate phase-1 landed via PR #693 (CharClass vocabulary + Rust-mirror structural scanner path), and point phase-2 at the new Class 5 Gap 3 row. Codifies the audit pattern: "this consumption gap has no substrate capability gap" claims must be verified by attempting the retype before the claim lands. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * resolve merge conflict on ROADMAP.md character-level row — keep phase-1 status edits + char_in_class interpreter-parity sibling row from main * docs(roadmap): name retraction mechanism explicitly in Class 5 Gap 3 audit note (PM review) * docs(roadmap): reconcile Character-level row title with body (per gpt-5.4 review) Row title still said 'consumption gap, not substrate gap' while the body block retracted that claim and cited Class 5 Gap 3 as a substrate dependency for phase-2. Title now matches body: mixed classification, consumption for steps 1+3, substrate for step 2. * docs(roadmap): correct Class 5 Gap 3 shape description + soften CharClass phase-2 blocker classification (per gpt-5.4 audit) gpt-5.4's review on 706 @ 71f46af caught that the row's "remaining gap" description was wrong: field-level shapes (nested records, list literals, declaration refs, Var refs, sum-variant literals) are supported today via FieldValue variants + lower_structural_field_value (dag.rs:328-353, lower.rs:2616+). The actual remaining gap is the top-level ValueBody boundary (non-scalar, non-record top-level bodies). The authority I cited — DOWNSTREAM_REQUIREMENTS.md:239 — is itself stale: it describes the pre-PR-B-unwind shape where FieldValue was LiteralBits-only. PR-B's unwind extended FieldValue to carry Reference / Record / List / Variant, moving the gap to ValueBody. Two fixes: 1. Rewrite the Class 5 Gap 3 row to describe the actual ValueBody boundary, point at code paths (dag.rs, lower.rs) as live authority, flag DOWNSTREAM entry as itself stale, and soften phase-2 CharClass blocker classification to "provisional pending reproduction." 2. Update the Character-level row's phase-2 block to name that the specific shape of the CharClass failure needs concrete reproduction from the escalating sub-child before the blocker is finalized. Recursive audit-pattern instance: the row I wrote to codify "verify live state before claiming substrate gap" itself failed to verify live state. Both incidents (2026-04-23 original row + 2026-04-24 my retraction row) are now cited in the audit-pattern sub-note as examples of the same discipline. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * WIP: gunbc Director * docs(cascade-promotion): resolve codex 4 BLOCKING findings at sha 0d6e7c3 Three substantive fixes addressing internal-consistency gaps in the cascade promotion PR caught by codex review at sha 0d6e7c3: 1. ROADMAP.md gate/baseline prose at :37 / :67 / :68 / :140 — bring lane acceptance bullets and Hand-Rust census paragraph in line with the updated lane summary rows. T-PB-A reads "0 per design-pure-bootstrap-zero (LIVE 2026-04-25)"; T-PB-B notes the TESTING.md residual carve-out is retracted under 0-floor with explicit migration to ExecuteCommand-based .dag TestClaim declarations. 2. docs/design-pure-bootstrap-zero.md promotion section — converted from future-tense ("This doc is PROPOSAL until promoted… promotion is a single Director-authored cascade PR…") to historical past-tense promotion-receipt framing ("This doc was PROPOSAL until promoted; promotion was a single Director-authored cascade PR that did all of the following atomically…"); blocking-clause struck through and resolved inline. Banner cites PR #782 explicitly. 3. docs/r2-structure.md 4th T-Substrate sub-lane scoping — kernel_algebra_ profile excluded (Map<String, AlgebraProfile> body, not list-of-sum; needs distinct ValueBody::Map substrate work, tracked separately as a future sub-lane). Sub-lane re-scoped to 2 consumers (tokenizer charclass phase-2 + Engine sharpened-(b) pilot enumeration), both sharing list-of-sum substrate work. Lane table, dependency DAG, and capacity summary updated for consistency (slot count 9-13, was 10-14). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): extend cascade across THESIS.md + sibling authorities Resolves claude REQUEST_CHANGES at sha fed6b03 — atomic-cascade self-violation. The promotion mechanism in design-pure-bootstrap-zero.md:18-22 explicitly names THESIS.md and "any other authority docs" as required retraction targets; the prior diff updated ROADMAP + r2-structure + design docs but left THESIS.md, compiler-std-consolidation.md, and r1-selfhosting- manager.md pointing at the now-SUPERSEDED ≤5-floor framing. Files: - THESIS.md (5 prose blocks updated): - :164 — facet 3 prose: residual carve-out retracted under 0-floor; tests migrate to ExecuteCommand-based .dag TestClaim declarations. - :248-252 — Self-hosting facet 3: same retraction; everything ports to .dag. - :253-283 — Cost-of-change paragraph + fixed-point acceptance: 0-floor target citing design-pure-bootstrap-zero.md as live authority; hand_maintained_src list shrinks to empty set. - :301-318 — Tests-are-structural-data block: residual carve-out retracted; predicate name pb_rust_tests_outside_residual_zero retained as housekeeping (semantically the residual is empty under cascade). - docs/thesis/compiler-std-consolidation.md (5 references): - Header link to design-pure-bootstrap-zero.md (LIVE) supersedes design-pure-bootstrap.md (SUPERSEDED). - :31 Bootstrap-shim positive-def: 0-floor target; PB-Bootstrap-Process lane named as the dissolution trigger for bootstrap.rs itself. - :87 hand-Rust paragraph: 0 target citing design-pure-bootstrap-zero.md. - :166 Tertiary ratchet: target shifts to 0 on both subsets; live authority re-cited. - :185 Related docs link. - docs/briefs/r1-selfhosting-manager.md (active dispatch brief): - SUPERSEDED-style banner at top: T-PB-A non-test target = 0 (not ≤5); T-PB-B residual carve-out retracted; predicate names retained for housekeeping; cascade-promoted authorities are source of truth. - Slice descriptions for T-PB-A / T-PB-B updated inline. - Framing-question + ask updated to 0-floor / no-residual framing. - Day-1 + up-to-director hand-off bullets updated. - Working-state checklist :111 ≤5 → 0 with cite. - Decisions log :164 ≤5 → 0-floor target updated. - docs/r2-structure.md §2 design call (RETRACTED block): - "Pre-promotion ≤5 irreducible-shim gate-name review" struck through in entirety (both Option A sharpen-and-keep and Option B rename are moot under 0-floor). Section preserved as audit-trail historical context. - Background-doc index: self-hosting anchor updated to design-pure-bootstrap-zero.md as live authority. - docs/design-pure-bootstrap.md SUPERSEDED banner (hardened per non-blocking suggestion): - Banner cites cascade promotion PR #782 explicitly. - New paragraph: "Treat all numeric floors below as retracted" with explicit lines named that quote in isolation (table row, body prose references). Prevents re-quoting from this doc as live authority. Cascade is now atomically consistent across: THESIS.md ↔ ROADMAP.md ↔ TESTING.md ↔ docs/thesis/compiler-std-consolidation.md ↔ docs/briefs/r1-selfhosting-manager.md ↔ docs/r2-structure.md ↔ docs/design-pure-bootstrap-zero.md (LIVE) ↔ docs/design-pure-bootstrap.md (SUPERSEDED). The (Resolved.) self-claim in design-pure-bootstrap-zero.md:29 now holds genuinely. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): correct ExecuteCommand runner-capability claim Resolves codex BLOCKING #1 at sha fed6b03 (P1 live-state violation): TESTING.md:195 and the matching prose in design-pure-bootstrap-zero.md:138 overstated live runner capability — claimed runner support landed in PR #688/#741 with "emit Rust, invoke rustc on output, check exit code" as a structurally-equivalent migration path. Verified against live sources: - src/v3/std/verification.dag:115-119 — ExecuteCommand predicate schema exists (declared via PR #678). - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:292-294 — M1.5 testgen harness allowlists ONLY `command == "true" && args.is_empty() && expect_exit == 0`. - src/v3/compiler/tests/integration/m1_5_testgen_test.rs:394-398 — panics fail-closed on any other shape with explicit "ExecuteCommand shell shape is not supported here (runner-owned — do not treat as ordinary false)". - src/v3/compiler/src/test_runner.rs:352-382 — Rust TestRunner has no match arm for ExecuteCommand; falls through to ClaimResult:: NotYetImplemented. Reality: a TestClaim declaring rustc/python/go invocation is structurally expressible as data today, but executing it is blocked. Full arbitrary-command runner support is the PB-Runtime lane's deliverable. Files updated: - TESTING.md:195 — capability state callout with file:line citations; "Full runner support — arbitrary command + args (rustc/python/go) with exit-code capture — is deferred to the PB-Runtime lane (Zero-Floor program)." Bullet about migration shape preserved as the cascade-named successor pattern, not as a live capability. - TESTING.md:205 — 0-floor-shape gate adds "AND the PB-Runtime lane lands the ExecuteCommand runner extension" as an explicit precondition. - docs/design-pure-bootstrap-zero.md:138 — same correction for the matching prose, with PB-Runtime named as the runner-extension dependency for boundary-test migration. - ROADMAP.md:54 (T-PB-B row) — "predicate schema landed PR #678; runner foundation in #688/#741 with `true`-no-args allowlist only — full arbitrary-command runner support deferred to PB-Runtime lane, blocking the actual boundary-test migration." Dependencies column extended to "DB-15 + T-TestGen + PB-Runtime". The (Resolved.) self-claim at design-pure-bootstrap-zero.md:29 still holds for atomic-cascade-across-authority-docs; this commit closes the remaining capability/claim mismatch flagged by codex. (Codex BLOCKING #2 — THESIS.md + compiler-std-consolidation.md still SUPERSEDED-pointing — was sha-stale; resolved in c85e691.) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(cascade-promotion): remove competing-authority hedge in R1 self-hosting brief Resolves codex BLOCKING at sha 0fb223a (P2 single-authority violation). The prior banner contained: > "Operationally R1 closure may still ship before the 0-floor is reached > — the ratchet ensures the trajectory; the gate's acceptance number is > what shifts." This contradicted ROADMAP.md:67 which now reads T-PB-A acceptance = 0. Two competing gate semantics in the cascade is exactly what the atomic-cascade clause forbids. Replaced with single-authority-honest framing: > "R1 closure now requires the 0-floor target by gate semantics: T-PB-A > and T-PB-B are R1 acceptance gates per ROADMAP, and the cascade > promotion changed their acceptance numbers to 0; R1 cannot close > while the SG-0 census carries non-zero hand-Rust." Plus minor sharpening: - "T-PB-A's non-test target is 0" → "non-test acceptance target is 0 per ROADMAP.md:67" (cite the authority). - T-PB-B note adds "blocked on the PB-Runtime runner extension" to keep the capability-state honesty consistent with the recent fix wave. - Predicate-rename housekeeping line moved into banner ("post-cascade housekeeping, not a pre-promotion blocker") — was implicit before. The brief now genuinely inherits the cascade-promoted gate; no competing release authority. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): R2 second-wave worker-escalation fixes Four substantive worker STOP-AND-ESCALATEs from briefs landed in PR #797. All four worker recommendations correct; each needs a Director call + brief update. ## sunny-otter-128 / unenumerated-effects — SPLIT into parser + substrate Worker correctly identified that brief req 2 (declared-effect carrier as part of fn type signature, per feedback_no_annotations) requires net-new parser surface: SurfaceType.Arrow and SurfaceItem.Fn at src/v3/std/parse_surface.dag:71-75 / :185-199 have ZERO effect slots. Without parser surface, every user function would have declared_effects = [] while inference returns non-empty — lens fires EffectLeakageError everywhere on enable. Worker rejected power-through and recommended sibling parser sub-lane (mirror of #797's ValueBody::Map parser split). Director picked split: - NEW: docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md Six reqs covering SurfaceType.Arrow/Fn declared_effects field + surface syntax + lookahead + body parser + lowerer extension + exhaustive-match audit + coproduct dissolution receipt. - MODIFIED: substrate brief banner + req 2 + slice step 1 narrowed to post-parser-extension scope. Pre-flight check NOT a parser-extension step; STOP if parser sub-lane PR not merged. ## sunny-deer-629 / unhandled-diagnostic-paths — REFRAMED to design/scoping Worker found load-bearing evidence at infer.rs:3693-3703: DB-11 deliberately strips refinements at operator dispatch as a designed-in fix for symmetric-operators failure mode. Brief's "attach where b != 0 as a proof for a / b" directly contradicts this design choice. STOP-3 (where-clause conflict with DB-11) is real; STOP-1 (substrate scope) needs net-new substrate (per-operator partiality fact + predicate- entailment check + asymmetric per-operand refinement-honoring) — M+ minimum. ownership_lens precedent in original brief is post-hoc observability, not proof carrier. Worker recommended redirect to design/scoping per nested-optional precedent. Director picked redirect. Brief fully rewritten as design/scoping with four-question structure: (1) DB-11 interaction analysis; (2) substrate proposal for proof-or- totality enforcement; (3) bypass-vs-park decision (a/b/c outcomes with acceptance-theatre risk on user-defined-total-wrapper-only); (4) Director-actionable recommendation. Output is doc PR. ## wise-pike-578 / cardinality-int-lit — RE-SCOPED option (C) Worker verified at HEAD: dsl/std/substrate.dag:31 has LitInt(Int) with Int = Int64; no Int128/UInt128 types; primitives.dag:134-136 closes TargetCarrier at Word64Carrier (no Word128Carrier). Choice (b) i128 implementation requires either path 1 (hierarchy refactor — contradicts non-goal) or path 2 (regen lie between substrate and emit — violates discipline). Worker leaned option (C) re-scope: land reqs 2+3+5 against existing i64; defer req 4 (i64::MIN smoke) to a sibling sub-lane that does proper Int128/Word128 substrate work. Director picked option (C). Brief req 1 re-scoped to drop canonical- carrier-widening; lane value comes from range facts + reconciliation narrowing + out-of-range diagnostic against existing i64. Req 4 explicitly deferred with sibling-sub-lane reference. Sibling sub-lane NOT to be authored or implied in this PR; tracked separately. ## wise-boar-480 / valuebody-map — cross-lane reassignment (no brief change) Worker correctly STOP'd per the brief's own pre-flight check: parser sub-lane has not landed; SurfaceExpr::Map not on main. Director authorized cross-lane reassignment: wise-boar-480 takes the parser sub-lane (t-substrate-valuebody-map-parser-worker.md) since they already have full investigation context. No brief changes needed; the routing decision is in the dispatch. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex P2 on Slice/Acceptance lagging req 1 re-scope Resolves codex P2 inline at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the prior re-scope (post-wise-pike-578 STOP) updated req 1 to defer carrier-widening but Slice + Acceptance + STOP-AND-ESCALATE still required widening LiteralBits::Int(i64) to an unbounded carrier and passing the i64::MIN smoke. Internally unsatisfiable. Fix: - Slice section retitled "range facts + reconciliation narrowing (against existing i64 carrier)" with explicit note about the re-scope. - Slice step 1 rewritten as "(NOT in scope — deferred)" — explicitly forbids touching LiteralBits::Int shape, dag_scalar_generated.rs regen for that variant, or tokenize i64 parse path. - Slice steps 2-5 reframed: range facts use i64-representable magnitudes; reconciliation narrowing uses existing i64 carrier; diagnostic only for i64-representable out-of-range; smoke tests for req 5 only (req 4 i64::MIN deferred). - Acceptance checklist updated: - Reqs 2, 3, 5 satisfied; reqs 1 + 4 explicitly noted as re-scoped/deferred. - LiteralBits::Int(i64) carrier untouched (no widening; no parallel; no shape change). - i64::MIN smoke marked DEFERRED with sibling-sub-lane reference. - STOP-AND-ESCALATE bullet 1 rewritten: "Pressure to widen the carrier" — explicit STOP if execution surfaces range-fact narrowing requiring carrier-widening; that's the boundary the re-scope drew; belongs in sibling Int128/Word128 sub-lane. Brief now consistently treats carrier-widening as out-of-scope across all sections. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): T-Substrate cardinality-int-lit — close codex BLOCKING #1 on range-fact carrier honesty Resolves codex BLOCKING #1 at sha e35103f on docs/briefs/t-substrate-cardinality-int-lit-worker.md:31. Real: the post-wise-pike-578 re-scope kept LiteralBits::Int(i64) carrier but req 2 required range facts using "the SAME magnitude carrier as req 1" — meaning i64-typed range bounds. u64's max (2^64-1) doesn't fit in i64; range fact for u64 would have to truncate, omit, or mirror in Rust (representation drift). All three options violate fail-closed declared-facts discipline (P1 / P3). Fix: - Req 2 rewritten to specify String-decimal representation: range_min_inclusive: String + range_max_inclusive: String fields on IntegerPrimitive carrying decimal magnitude (e.g., "-128"/"127" for i8; "0"/"18446744073709551615" for u64). - Explicit reasoning why String-decimal: u64's max doesn't fit in i64; binding range bounds to literal carrier forces truncation/ omission/mirror-drift; all violate fail-closed declared-facts discipline. - Bridge framing: String-decimal is pending the sibling Int128/ Word128 sub-lane; both range bounds and literal payload migrate to typed carrier when that lands. - Req 3 updated for String-decimal comparison semantics: reconciliation parses both bounds and literal magnitude into a common comparison space (i128 host comparison primitive — host narrowing, NOT carrier widening). Bounded by what the i64-typed literal can express; any i64-representable literal compares against any width's String-decimal bound. Carrier discipline preserved. Codex BLOCKING #2 (Slice/Acceptance contradicting req 4 deferral) is sha-stale — already resolved at 3e142d1. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): cardinality-int-lit — close codex BLOCKING on Slice/Acceptance still i64-typed Resolves codex BLOCKING at sha 0815189 (post-#799-merge feedback). Real residual: req 2 specifies String-decimal range bounds (to cover u64::MAX which doesn't fit in i64) but lines 31, 44, and acceptance bullet still referenced "i64-bounded magnitudes" / "Int64 carrier" / "i64-representable magnitudes" for the range facts. Two incompatible authorities for the same range-fact shape — would let a worker satisfy the slice while truncating/omitting u64 bounds (P3 fail-closed violation). Fix: - Line 31 (req 1 re-scope clarification): updated to explicitly state "range facts (req 2) use String-decimal representation (width- independent; covers u64::MAX which doesn't fit in i64)". Distinguished literal *payload* (stays i64) from range-bound *representation* (String) — both serve req 1's "no carrier widening" boundary. - Line 44 (slice step 2): updated from "Range bounds use i64- representable magnitudes" to "Range bounds use String-decimal representation per req 2" with concrete example (u64 bounds). - Acceptance bullet: updated from "Range facts on integer algebras (substrate-declared, not Rust-mirrored)" to add "using String-decimal representation ... width-independent; u64 bounds expressible without truncation." The brief now consistently treats range bounds as String-decimal across req 2, req 3, slice, acceptance, and the req 1 clarification — no remaining authorities saying i64-typed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): redirect unenumerated-effects chain to closed-system framing User + PM exchange 2026-04-25 surfaced that the in-flight effects chain was importing wrong assumptions from external languages (declared-effects-as-annotation + lens-vs-declaration check). Right framing under gunbc's closed-system discipline is parallel to complexity: every effect derives structurally from the composition of typed primitive operations; nothing can hide because there's no escape hatch; nothing needs annotation because the structure IS the registry. Four doc-only actions: 1. NEW docs/briefs/t-impossiblebugs-unenumerated-effects-design.md. Frames the closed-system answer with PM's 5-behavior synergy table (Value/Transform/Branch/Loop/Bind as universal compositional-fold pattern). Four worked examples; aggressive reading on redundancy (compile-error-by-construction via referential-transparency proof; reread() primitive for legitimate cases); implementation-brief shape in §Q6. 2. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-worker.md. 3. SUPERSEDED banner on docs/briefs/t-impossiblebugs-unenumerated-effects-parser-worker.md. Notes Fn→Arrow refactor brief stays dispatchable as independent value. 4. THESIS:345-347 bug-class amendment: Tier 1 impossible-by- construction framing replaces lens-detection framing. Memory file feedback_closed_system_effects.md saved separately; cross-link added to feedback_construction_over_ratchets.md. Net cost: doc-level cleanup. Zero substrate code rework. Foundation (OperationEffect + service-call infrastructure + 5-behavior substrate) already exists. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): Q5.5 — operation type-signature shape IS the effect Per PM convergence review on #808 + user's deeper 2026-04-25 framing: the closed-system framing landed in #808 retired the user-facing annotation but kept OperationEffect taxonomy as substrate-level tagging. User's deeper framing: the taxonomy ITSELF is parallel-representation — operations are intrinsically read-shaped or write-shaped via their TYPE-SIGNATURE SHAPE (returned-modified-resource → write; returns- derived-value-only → read). Tagging operations with Read | Upsert | Create | Append | Delete names what the structure already says. Three changes: 1. Design doc Q5.5 added — "OperationEffect taxonomy: retain as normalized view, or retire as parallel-representation?" - Two paths: (i) tags derived from signature shape (acceptable normalized view) vs (ii) tags declared per-primitive (parallel- representation; retire). - Audit-as-existence-check (Q4 req 2 reframed): all effectful primitives derive cleanly from signature shape → path (i); any primitive needs hand-declared tag → path (ii) by existence proof. - Director default: path (ii). Logging primitives that return Unit are likely the audit's existence-proof. - Two design-question resolutions: (a) external effects not in return type → resource-threading discipline (typed param returned modified, IO-monad-without-the-monad pattern); (b) transactional grouping → derived structural fact from Bind composition + typed transaction primitives. 2. Q4 reqs revised: req 2 from "tag every primitive with explicit OperationEffect signature" to "audit-as-existence-check that every primitive's type signature derives the right effect classification"; req 3 added (resource-threading discipline); req 6 added (transactional-pattern lens). Req 1 (effects lens) anchors on operation type-signature shape, not on hand-declared tags. 3. THESIS:345-347 amendment strengthened — "operations are intrinsically read-shaped or write-shaped via their type-signature shape; consumers walk the signatures directly; there is no parallel taxonomy or annotation layer to declare or maintain. Tracking effects as a separate enumerated concept IS the bug pattern, dissolved by construction." Plus references to resource-threading discipline + transactional grouping as derived structural fact. Memory file feedback_closed_system_effects.md updated to reflect the deeper framing (type-signature-shape, not taxonomy-tagging) + resource-threading discipline section + transactional-patterns section. Net cost: doc-only delta on top of #808. Substrate retirement (OperationEffect enum + derive_op_effect + idempotency.dag re-anchor) deferred to the audit-as-existence-check phase of the implementation brief; surfaced as Q5.5 OPEN CALL. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex BLOCKING — honest live-state on signature-shape coverage Resolves codex BLOCKING at sha d49ce79 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:116. Real: the prior text claimed service primitives "already carry typed effect signatures" presenting future audit-state as current substrate fact (P1 violation). My Q5.5 amendment at 2dc656b partially fixed the OperationEffect line but left a parallel over-claim on the new "signature-shape coverage" framing. Fix: Q4 substrate-state listing rewritten to honestly distinguish: - Live: Behavior enum + substrate foundation (the principle that operations should carry signature shape). - Incomplete: signature-shape coverage across actual primitives. HTTP-derived primitives carry implicit shape via derive_op_effect's method-table; logging/mutation primitives that return Unit or don't thread their target resource do NOT carry the structural shape that would express read-vs-write. Achieving full coverage is required work under reqs 2 + 3, not a current fact. - Pending audit-as-existence-check: OperationEffect + derive_op_effect (path (i) vs (ii) per Q5.5). Honest live-state callout added explicitly: "the closed-system FOUNDATION (5 behaviors + DAG substrate + the principle that operations should carry signature-shape) is live. The IMPLEMENTATION COVERAGE across all effectful primitives is partial. Req 2 + req 3 are the work that closes the gap." Brief now distinguishes principle-is-live (foundation) from coverage-is-partial (audit work) without conflating them. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * WIP: gunbc Director * docs(closed-system-effects): Q4.5 — load-bearing pre-conditions for closed-system claim Per PM follow-up review on #808 + user's stronger discipline framing ("substrate must make bypass structurally impossible at every layer of the transport stack"): the closed-system claim is honest only when typed primitives ARE the path. Today two structural holes exist where bypasses sidestep the typed-primitive substrate. Both surfaced explicitly as Q4.5 pre-conditions — load-bearing for the lens's coverage claim. Three changes: 1. NEW Q4.5 section "Pre-conditions (load-bearing for the closed- system claim)" inserted between Q4 and Q5: P1 — Extdeps typed-primitive consumption structurally enforced. Substrate must make `messages: Json` impossible to declare in service definitions; typed `LlmMessage` / `ContentBlock` / `GitHubAuthToken`-with-full-scopes are the only path. Tracked debt at ROADMAP.md:153-154 (LLM provider flattening) + `dsl/extdeps/github/auth.dag:13-24` (scopes/expires_at discarded). Required prereq for full lens coverage; lens can land first + surface structural-coverage-gap diagnostics on bypass surfaces so the gap becomes visible rather than silent. P2 — `ExecuteCommand` fully materialized as typed runner primitive. TESTING.md (post-#782) committed to 0-residual but ExecuteCommand isn't fully materialized; deleting Rust boundary tests creates verification gap. Already named under PB-Runtime in Zero-Floor; signal pending. Pre-requisite for ANY Rust boundary-test deletion. 2. Old leftover duplicate Q5 section deleted (artifact from prior Q5/Q5.5 reshape; second copy of asymmetric-tightening text was in the file alongside the earlier Q5 instance). 3. Worker-discretion-vs-Director-call section in Q4.5: lens implementation worker dispatchable now (reports gaps as findings); P1 closure is substantive substrate work touching extdeps (dedicated lane); P2 closure is PB-Runtime (signal pending). Net: design doc now honestly distinguishes principle-is-live (Q4 rewrite at 191be31) from coverage-is-partial (Q4.5 prereqs named explicitly). The closed-system claim has explicit pre- conditions documented; implementation brief discovers them as known dependencies, not as STOP-AND-ESCALATEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): align Q6 + capacity-table with Q5.5 path (ii) default Resolves claude APPROVE_WITH_COMMENTS at sha 191be31 on #808. Two real residuals after the Q5.5 reframe: 1. Q6's reqs/STOPs/acceptance still framed under path (i) — said "audit + tag std/ primitives — every effectful primitive carries an explicit OperationEffect signature." Directly contradicted Q4 (post-191be310b) + Q5.5's path (ii) default + the THESIS amendment ("there is no parallel taxonomy to declare or maintain"). Worker reading Q6 in isolation would author the retracted shape. 2. Capacity / sequencing table line about "audit lane (tag std/ primitives with effect signatures)" carried the same stale framing. 3. Q6 STOP "primitive performing side effects without an OperationEffect tag" assumed tag-as-authority; under path (ii) the STOP shape is "primitive whose signature doesn't structurally reveal its effect." Plus the duplicate Q5 section claude flagged at :184-191 is sha-stale (already fixed at f073aa9 Q4.5 commit). ## Q6 fixes - Reqs renumbered + reframed: - Req 1 anchors on operation type-signature shape (not hand-declared OperationEffect tags); composition reads from signature shape per Q2 table. - Req 2 changed from "audit + tag every primitive" to "audit-as-existence-check" — verify signature-shape coverage; ANY primitive needing a hand-declared tag IS the existence-proof for path (ii) retirement. - Req 3 added: resource-threading discipline applied to existing primitives (logging that returns Unit gets reshaped per audit). - Req 6 added: transactional-pattern lens (Bind composition + Transaction → Transaction'). - Req 7 added: asymmetric-tightening worked example in PR body (per claude review observation; the one place declaration-shaped surface re-enters). - Req 8 (was 5): tests now reference signature-shape derivation explicitly, not tag lookup. - STOPs reframed: - "OperationEffect retirement decision" — audit produces path (i) vs (ii) verdict; substrate retirement is its own dedicated sub-lane; this lane does NOT absorb it. - Pure/impure carrier STOP notes that "pure" should also derive from signature shape (pure functions don't return modified resources) — so the STOP itself may dissolve under further design. - Q4.5 P1 explicitly NOT a STOP — lens reporting structural- coverage-gap on extdeps bypass surfaces is the lens delivering its foundation-gap-visibility value. - Q4.5 P2 explicitly independent — lens doesn't depend on ExecuteCommand materialization. - Acceptance extended: lens reports gap diagnostics on P1 bypass surfaces; audit produces existence-proof verdict for Director re-decision; asymmetric-tightening worked example in PR body. ## Capacity / sequencing table Replaced "1 audit lane (tag std/ primitives with effect signatures)" with "1 audit-as-existence-check lane (verify primitives' signature- shape coverage; NOT 'tag every primitive') — produces the path (i) vs (ii) verdict on OperationEffect retention." Added Q4.5 P1+P2 prereq lanes to the net summary. Closing line: "The taxonomy- retirement scope (substrate-side) is not in this lane — it's surfaced by audit and routed to dedicated retirement lane if path (ii) wins." Net: design doc internally consistent across Q1-Q6 + Q4.5 + capacity table. Worker reading Q6 in isolation now sees path-(ii)-default framing matching Q4 + Q5.5 + THESIS amendment. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close BLOCKING — P2 stale, ExecuteCommand landed via #792 Resolves codex inline BLOCKING at sha 191be31 on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:150. Real: my Q4.5 P2 framing described ExecuteCommand as still NotYetImplemented (M1.5 allowlist + Rust TestRunner returning NotYetImplemented), but PR #792 landed the PB-Runtime ExecuteCommand extension before this PR's authoring. TESTING.md:195 capability-state callout confirms: - Rust TestRunner + M1.5 testgen harness share one std::process path for arbitrary command + args + expect_exit_code. - M1.5 allowlist + fail-closed panic retired. - Distinguishable ClaimResult::Fail messages for spawn / timeout / policy / exit-mismatch. - Linux unshare(1) namespace isolation on host-allowing systems. - T-PB-B-1 boundary migration example landed. Fix: P2 section rewritten: - Header retitled "ExecuteCommand runner primitive: LANDED (PR #792); residual is bulk-migration." - Status update naming PR #792 + the post-#792 capability state (allowlist retired, etc.). - Honest acknowledgement: "My earlier P2 framing was stale." - Residual narrowed to bulk-migration of existing Rust Command::new boundary tests (tracked as ROADMAP residual, not lens prereq). - Sequencing reframed: P2 was always orthogonal to the effects lens itself; bulk migration proceeds at its own pace; lens not blocked. Q4.5 footer updated: - "P1 + P2 closure" → "P1 closure (P2 runner-primitive landed via #792; only consumer-side bulk migration remains)" - Worker-discretion-vs-Director-call P2 line updated: "runner primitive landed; only consumer-side bulk migration remains; tracked as ROADMAP residual, independent of the lens." Q6 STOP for P2 updated: - "the lens itself doesn't depend on P2; only TESTING.md's 0-residual claim does" → "runner primitive landed via PR #792 (post-Q4.5- authoring update). The lens itself never depended on P2; bulk consumer migration is residual ROADMAP work and remains independent of this lane." Brief now reflects live state. The closed-system claim's prereq landscape is honest: - P1 (extdeps typed-primitive consumption): real prereq, tracked debt at ROADMAP:153-154. - P2 (ExecuteCommand runner): satisfied via #792; bulk migration is consumer-side residual, not foundation work. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(closed-system-effects): close codex non-blocking — capacity-table P2 framing stale Resolves codex non-blocking finding at sha bcac41b on docs/briefs/t-impossiblebugs-unenumerated-effects-design.md:270. Real residual: capacity-table line still listed P2 as "`ExecuteCommand` materialization" prereq + framed both P1 and P2 as "pre-existing tracked-debt" — but my prior 57a9b13 fix established that PR #792 already landed the runner primitive, so P2 is no longer a materialization prereq. Fix: capacity-table P2 line rewritten to distinguish P1 (real prereq) from P2 (residual, not prereq): - P1: extdeps typed-primitive consumption — pre-existing tracked debt at ROADMAP:153-154; load-bearing for the lens's full-coverage claim. - P2: ExecuteCommand runner primitive landed via PR #792; only consumer-side bulk migration of existing Rust Command::new boundary tests remains (tracked as ROADMAP residual, independent of the lens; not a materialization prereq). Brief now consistently treats P2 as bulk-migration-residual across: - §Q4.5 P2 section header (LANDED via PR #792; residual is bulk-migration). - §Q4.5 footer (P2: runner primitive landed; only consumer-side bulk migration remains). - Q6 STOP for P2 (runner primitive landed; bulk migration is residual ROADMAP work). - §Capacity / sequencing impact (P2 as residual, not prereq). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix stale ROADMAP citations 153-154 → 348-349 Codex finding on PR #808 sha ece964e: lines 153-154 are unrelated target-grounding prose; the matching extdeps typed-primitive bypass entries (LLM service flattening, GitHub auth model bypass) live at ROADMAP.md:348-349. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): fix third stale ROADMAP citation at line 271 Codex follow-up on sha 2552ca3: prior fix missed a third occurrence at line 271 in the §Q4.5 capacity table. Now consistent with lines 139 and 173 (ROADMAP.md:348-349). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(effects-design): clarify cross-manager note avoids 'tagging' ambiguity Codex flagged 'Effect-signature tagging on std/ primitives' as potentially contradicting Q5.5/THESIS single-authority claim. Reqs 2 (lines 124/240) already explicitly say 'NOT tag every primitive' — but the cross-manager line used sloppy wording. Reworded to make explicit that the audit walks signature shape; no parallel tag added. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): author B1-B4 per debt-paydown synthesis #810 §5 - B1: Tier 0 Go UnknownVariant fabrication → EmitError::VariantParentNotFound - B2: Tier 0 lower_fn_body Arrow re-derive → fail-closed diagnostic + seed-phase root cause - B3: Tier 0 lens fold ambiguous fallback → require structural template-formal edge - B4: Tier 1 program brief — Identity-Carrier Substrate Pass (M; primary recommendation) B4 framed per feedback_groundedness_gates_lenses (revised 2026-04-25): language vocabulary is primitives + namespacing only; no escape syntax; the §0 sentinels are the compiler itself failing to use primitives + namespacing internally. Eight surface sites dissolve via four substrate carriers (DeclarationRef, structural fold-shape carrier, structural emit-helper carrier, structural extdeps-fixture-set carrier). B1-B3 are independent; dispatch in parallel. B4 is sequential program work; sub-brief dispatch (B4.1-B4.12) follows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B1 — drop incoherent inner-fallback non-goal Codex P2: the non-goal line excluding the inner declaration().name unwrap_or_else fallback contradicted Slice step 2, which replaces the whole chain with let-Some-else-return. Both fallbacks are in scope by construction; remove the contradictory non-goal. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — fix §Frame vocabulary enumeration to canonical 6 connectives PM REQUEST_CHANGES: §Frame listed '4 type connectives (Conjunction | Disjunction | Cardinality | Bit)' which contradicted the canonical thesis source. Replaced with the canonical 6 (Atom | Conj | Disj | Arrow | Cardinality | Instantiation) per docs/thesis/the-substrate-two-coordinated-shapes.md §'The vocabulary closes here'. Also removed 'typed substrate carriers' from the vocabulary list — substrate carriers are defined using the vocabulary, not part of it. Added a clarifying note that B4's carriers (DeclarationRef, fold-shape, emit-helper, extdeps-fixture-set) are typed declarations composed from the vocabulary, not vocabulary extensions. Per feedback_verify_thesis_claims: brief framings citing thesis structure must ground in the canonical source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — reframe B4.1 as consumer migration; cite live substrate authority Codex BLOCKING: B4 §Frame copied stale feedback vocabulary instead of naming the live substrate authority. Two coordinated fixes: 1. §Read first cites src/v3/std/substrate.dag (live .dag substrate authority) and src/v3/spec/v3_l1.dag:69 (DeclarationRef sentinel meta-type — already exists with consumers in verification.dag, emit_model.dag, python.dag). 2. Phase 1 #1 reframed: 'land DeclarationRef' → 'consume the existing DeclarationRef'. The work is consumer migration + any role-extension layer the audit reveals, NOT designing or landing the carrier. Phase 1 #2-#4 (fold-shape, emit-helper, extdeps-fixture-set carriers) keep their 'new' framing but explicitly require sub-briefs to grep src/v3/std/ + src/v3/spec/ for existing authority before authoring 'design and land' framing — per feedback_verify_thesis_claims + feedback_emitter_workaround_is_gap_symptom. Acceptance + sub-brief dispatch order updated to reflect B4.1's consumer-migration shape. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — tighten Phase 1 umbrella sentence The umbrella 'Land the typed carriers into src/v3/std/' framing was stale after f52e2ce's reframe of #1 to consumer-migration. Replaced with audit-first wording that covers both the consume-existing case (#1) and the design-and-land case (#2-#4 if their audits show real gaps). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(briefs): B4 — consistency fix for 'carriers B4 lands' wording Codex APPROVE_WITH_COMMENTS: §Frame still said 'carriers B4 lands' which conflicted with the post-reframe reality that B4.1 consumes the existing DeclarationRef. Updated to 'consumes or lands' with explicit existing-authority citation and audit-pending caveat for B4.2-B4.4. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Summary
Carries forward two B4 fixes that landed after PR #814's merge window:
PR #814 captured the connective enumeration fix (`488f6c15d`) but merged seconds before these two landed.
Doc-only diff. No code change.
Test plan
🤖 Generated with Claude Code